The URL I’ve linked to isn’t the real Apple technology company that makes shiny iPhones, Homepods, and iMacs. Instead, it’s a Unicode domain which - rather than using the conventional ASCII characters that make up the vast majority of websites you’re likely to visit - contains foreign characters.

So the “а” of аpple.com is actually a Cyrillic “а” (U+0430) rather than the ASCII character “a” (U+0061).

What’s that? You couldn’t tell the difference? No, neither can I. And, as we’ve described before, that’s a problem that phishers and online crooks are only too happy to take advantage of in their pursuit of your passwords and other sensitive information.

You see, it’s not just “а” and “a” that can be mixed up. There are countless ways in which bad guys can take advantage of the many Unicode characters that look remarkably similar to common ASCII characters. Which means that you and I are at risk of visiting a site believing it to be legitimate, when in fact it’s designed to scam us in what is known as an IDN Homograph attack.

Browsers are beginning to get better at warning users when they visit a site with an internationalized domain name (IDN), with some now displaying the URL in the browser bar in its Punycode form. That means you might spot you’re visiting xn–pple-43d.com rather than the real apple.com

But human nature means that we will more-often-than-not fail to check the browser bar, and not notice that we’re not on the website we intended.

For that reason, I strongly recommend that you get some help.

There are a range of browser extensions and plugins that can warn you when you visit a website with an internationalized domain name. Having tried a few solutions, my preference is for a browser add-on called IDN Safe.

IDN Safe not only warns you that you are visiting a URL with an internationalized domain name, but it also *blocks* the webpage (which is far more likely to grab your attention!).

Of course, if you *did* want to visit that URL it would be a nuisance if you were now being blocked from reaching it. So, IDN Safe includes a whitelist feature to allow you to visit specific sites that you decide are legitimate.

IDN Safe isn’t for everyone. In particular, if you are - say - Chinese and in the habit of visiting websites that take advantage of internationalized domain names you may find it a ruddy nuisance. But, for most of us, I think it’s a sensible addition to our security toolbox - and may stop you from being phished or scammed one day.

About the author, Graham Cluley

Graham Cluley is a veteran of the anti-virus industry having worked for a number of security companies since the early 1990s when he wrote the first ever version of Dr Solomon's Anti-Virus Toolkit for Windows. Now an independent security analyst, he regularly makes media appearances and is an international public speaker on the topic of computer security, hackers, and online privacy.

I was sure that Firefox 58.0.2 (64bit) on Win 7 Prof. was secure. This happened to me a couple of days ago: Mozilla FF browser froze while checking a web site that had Kaspersky’s “green seal”. I couldn’t take screenshots at all. None of the usual hacks worked. I shut down the computer, started 15 minutes later and there it was»> The frozen browser. So I ended up taken pictures with my camera.
Mozilla has not responded. Kaspersky helped me by fixing the problem. I have sent Kaspersky the 14 pictures.
With all these problems shouldn’t we be concerned of having Mozilla FF, Kaspersky and others holding our passwords to everything? BHH are getting ahead of the game.

Hello again Graham. Copy and paste your head title» “𝖨𝗍’𝗌 𝖾𝖺𝗌𝗒 𝗍𝗈 𝖻𝖾 𝗍𝗋𝗂𝖼𝗄𝖾𝖽 𝖻𝗒 𝖺 𝖴𝗇𝗂𝖼𝗈𝖽𝖾 𝖴𝖱𝖫”.«
and try to change the font to any of the other most used fonts. »It stays the same« “CAMBRIAMATH” WHY?
Regards,
Alfonso

When google just released chrome and its store for apps. In the beginning I was excited and curious. But later I noticed that these extensions need to much my personal info. It might be that some of them are time savers, but unrelated permissions giving a big stop of using them.

Another issue are browsers on mobile devices„, I haven’t tested lately but last time I checked my iPad there was no real URL on the status bar.
And seemingly most folks now use mobile devices to browse :o